Passbolt records
4 published records for vendor passbolt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-348 Use of Less Trusted Source1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
27Monitor | CVE-2024-33669No exploit | An issue was discovered in Passbolt Browser Extension before 4.6.2.passbolt · passbolt browser extension · CWE-200 | Medium6.8 | — | 0.6% | Apr 25, 2024 |
21Monitor | CVE-2017-1000442No exploit | Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspacepassbolt · passbolt api · CWE-79 | Medium5.4 | — | 0.5% | Jan 2, 2018 |
17Monitor | CVE-2024-33670No exploit | Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the craftpassbolt · passbolt api · CWE-79 | Medium4.3 | — | 0.5% | Apr 25, 2024 |
8Monitor | CVE-2025-27913No exploit | Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), canpassbolt · passbolt api · CWE-348 | Low2.1 | — | 0.2% | Mar 10, 2025 |
- CVE-2024-3366927Monitor
An issue was discovered in Passbolt Browser Extension before 4.6.2.
MediumCVSS 6.8No exploitEPSS 1%passbolt · passbolt browser extensionApr 25, 2024
- CVE-2017-100044221Monitor
Passbolt API version 1.6.4 and older are vulnerable to a XSS in the url field on the password workspace
MediumCVSS 5.4No exploitEPSS 1%passbolt · passbolt apiJan 2, 2018
- CVE-2024-3367017Monitor
Passbolt API before 4.6.2 allows HTML injection in a URL parameter, resulting in custom content being displayed when a user visits the craft
MediumCVSS 4.3No exploitEPSS 0%passbolt · passbolt apiApr 25, 2024
- CVE-2025-279138Monitor
Passbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), can
LowCVSS 2.1No exploitEPSS 0%passbolt · passbolt apiMar 10, 2025